An investigator with an assistant can sort leads and prepare more work. In an espionage campaign, that added capacity serves an unauthorized purpose.
An analogy for the mechanism; not an additional claim about the incident.
KEEP THE EVIDENCE IN VIEW
What we know. What we don’t.
Reported outcomes
A suspected Russian-linked operator automated spying, including malware revisions. Stolen material included drone technology and government records. Anthropic ↗
Important limits
A targeted organization is not necessarily a breached organization.
Targets are not confirmed victims. The number does not establish how many systems were compromised.
The report covers December 2025–August 2026 overall. That window is not the start and end date of this individual case.
WHY IT MATTERS
The lesson beyond this one case.
Espionage is the covert collection of information. Automating supporting work can change what a small team is able to attempt.
What happened in response? +
Anthropic reports disrupting abusive accounts. An account ban does not establish that the broader operation has ended. Anthropic ↗
FROM THE INCIDENT TO THE DEFENSE
What could help an organization?
The reported espionage campaign includes a linked operation that lured travelers through fake update or sign-in prompts.
Managed software installation, trusted update channels, and phishing-resistant sign-in can help protect staff when a convincing prompt asks them to install something or sign in.
What this does—and does not—establish +
The traveler example comes from a linked subcampaign. It is not an established entry route for every reported target.
Security teams can connect suspicious device activity with account use and access to sensitive records, then contain the affected device or account.
What this does—and does not—establish +
AI-assisted analysis still needs reliable records and validation; it cannot reveal activity on systems the team cannot observe.
Editorial connections to relevant controls, not evidence that a particular technology would have prevented this case. Each guide links to the security guidance behind its recommendations.
Corroborating reporting on the CaptiveCrunch subcampaign that Anthropic links within GTG-20006.
Microsoft observed AI-supported operations by Storm-2945 since February 2026, and manipulation of hospitality guest-network traffic since early May. Microsoft Threat Intelligence ↗
Travelers were redirected to fake update or sign-in prompts. The delivered software could steal information or provide remote access. Microsoft Threat Intelligence ↗
Microsoft associated Storm-2945 with Midnight Blizzard, while saying the initial entry into guest-network systems remained under investigation. Microsoft Threat Intelligence ↗
WHAT THIS CAN LOOK LIKE
A traveler joins guest Wi-Fi. A convincing prompt appears to fix the connection. Following it can hand information or access to an attacker.
This is a simplified composite of the reported technique, not a reconstruction of a named victim.
February describes the actor activity Microsoft observed; early May describes CaptiveCrunch. Neither dates every intrusion grouped under GTG-20006.
Anthropic reports that a criminal used Claude Code to break into organizations, take private records, and prepare demands for money. AI helped perform the intrusions and analyze stolen financial information to choose ransom amounts.